Vendor Due Diligence
Vendor due diligence is the process of gathering and reviewing information about a supplier or other third party before entering into or continuing a business relationship with them. The goal is to understand who you are dealing with and to identify possible risks in areas such as finances, legal standing, and operations. It is a practical risk-checking activity rather than a legally defined term, though it may support broader compliance obligations.
Vendor due diligence (VDD) is a structured evaluation process in which an organization collects and assesses financial, legal, operational, and related information about a vendor, supplier, or comparable third party to determine the risks of establishing or maintaining a relationship. In a third-party risk management context, it generally functions as a pre-engagement and ongoing-monitoring control to verify vendor legitimacy and surface apparent risks. Note that the term carries a distinct meaning in mergers and acquisitions, where VDD refers to an in-depth analysis of a target's financial, legal, and operational aspects prepared on behalf of a seller to identify risks ahead of a transaction; practitioners should confirm which usage applies in a given setting. VDD is a business and risk practice rather than a binding legal requirement in itself, although it may be undertaken to help satisfy applicable regulatory or contractual obligations, which vary by jurisdiction and sector.
Why it matters
Organizations increasingly depend on third parties for critical functions, and a vendor's weaknesses can become the organization's own. Vendor due diligence matters because risks in a supplier's finances, legal standing, or operations can propagate into the engaging organization, potentially disrupting operations, exposing sensitive data, or creating regulatory or contractual exposure. Reviewing this information before and during a relationship allows an organization to make an informed decision about whether and how to engage a given vendor.
VDD generally functions as both a pre-engagement control, used to verify that a prospective vendor is legitimate and to surface apparent risks, and an ongoing-monitoring control applied over the life of the relationship. This dual role reflects that vendor risk is not static: a supplier's circumstances can change after onboarding, so a one-time check at the outset may not remain adequate. In most cases, VDD is undertaken as a business and risk-management practice rather than because a single statute mandates it by name.
Readers should note that VDD is not itself a binding legal requirement. It may, however, be undertaken to help satisfy applicable regulatory or contractual obligations, and those obligations vary considerably by jurisdiction and sector. Whether and to what depth due diligence is expected in a specific situation depends on the applicable law, the nature of the relationship, and the risks involved, and requires professional judgment rather than reliance on a general definition. The specific obligations that VDD might support are outside the scope of this entry and should be verified against current authoritative sources.
Who it's relevant to
Inside VDD
Common questions
Answers to the questions practitioners most commonly ask about VDD.
